HackingData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
The LoveSac Company
bd_a32eb25ec7419355 · schema v1 · pii pii-v1
Full breach record for The LoveSac Company →The LoveSac Company notified the New Hampshire Attorney General of a data event affecting 6 NH residents. Unauthorized access occurred between Feb 12 and Mar 3, 2025, involving copying of files containing names and SSNs. LoveSac became aware on Feb 28, 2025. Response included notifying federal law enforcement, providing 24 months of Experian credit monitoring, and reviewing security policies. Investigation is ongoing.
Leak gap clock✗ Leak >180d27 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
A leak claim by ransomhub about this victim predates this filing by 189 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_2ab4dbfe2f4645b5Indiana State AGfiled 2025-09-04(1d gap)Candidate
- bd_55ce6f94b7259130Indiana State AGfiled 2025-09-04(1d gap)Verified
- bd_5ab5de4fec271deeMaine State AGfiled 2025-09-04(1d gap)Candidate
- bd_81c14587331502c2Maine State AGfiled 2025-09-04(1d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 1d gap
- bd_8f82ad1bad5501b1Vermont State AGfiled 2025-09-04(1d gap)Verified
- bd_bedf34d850941636New Hampshire State AGfiled 2025-09-04(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/lovesac-20250905.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 5, 2025
- Raw hash
- b1649202c41dd4b82f70620f44727f29a583149b6fd034d2e3ad4845ceec5054
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- The LoveSac Companynorm: the lovesac
- Domain
- lovesac.com
Incident
- Discovered
- Feb 28, 2025
- Materiality determined
- —
- Notification sent
- Sep 4, 2025
- Affected individuals
- 6
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1119 Automated CollectionT1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 27 weeks(189 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.